ãã¡ãã®ã¤ãã³ãã«ãããã¾ãã¦ãã¾ããã
https://owasp-kansai.doorkeeper.jp/events/172199
ä¼å ´ã¯å¤§éªäº¬æ©ã«ããQUINTBRIDGEã¨ããNTT西æ¥æ¬ããã®ã¤ãã³ãã¹ãã¼ã¹ã
https://www.quintbridge.jp/
ãã¡ããããããï¼è±ªå¢ãªã¨ããã§ãããããã¦ãã¾ããã
å
容ã¯ååã«åºèª¿è¬æ¼çãªãã®ã4æ¬ã
ä¼æ©ã¨æè«ã¿ã¤ã ãæãã å¾ãå¾åã¯LTã¨è¤æ°ã®BoFã®åæéå¬ã§ã
åå è
å人ã¯è¦ãããã®ãè¦ã«è¡ãã¨ãããã®ã§ãã
ããã¡å¸°ã£ã¦ã¬ããã¾ã§ãã¤ãã³ãã®èãæ¹ã®ãã¨ã以ä¸ããããããªãã®æ®´ãæ¸ãã¡ã¢ã§ãã
è¬æ¼ã«ãã£ã¦ã¯å¾ã»ã©è³æãå
¬éããããããªã®ã§ã詳細ã¯ãã¡ããåç
§ãã ããã
1. ãªã¼ããã³ã°
- OWASPã¨ã¯
- Open Worldwide Application Security Projectï¼ã¿ããªã®åã§ä¸çä¸ã§ã¤ããããããã®ã»ãã¥ãªãã£ãä½ã¨ãããæ´»åï¼
- ä¸æåã¯ãã¿ããªã®å㧠ã¦ã§ã㧠ã§ããããã® ã»ãã¥ãªãã£ã ä½ã¨ãããæ´»åãã ã£ããã©ãå¤ãã£ãã£ã½ãã§ãã
- åæ¹åã³ãã¥ãã±ã¼ã·ã§ã³ã大äºã«ãã¦ãã
- Open Worldwide Application Security Projectï¼ã¿ããªã®åã§ä¸çä¸ã§ã¤ããããããã®ã»ãã¥ãªãã£ãä½ã¨ãããæ´»åï¼
- OWASP Kansai 10å¹´ã®æ©ã¿
- 2014å¹´3æã¹ã¿ã¼ã
- åå åæ°ã©ã³ãã³ã°åºã¦ãã¦ããã£ã
- 2022å¹´2ææç¹ã§6ä½ã ã£ãã®ã«ããã¤ã®ã¾ã«ã4ä½ã«ä¸ãã£ã¦ã^^;
- è¨é²ãæ®ã£ã¦ããéãã§ã¯ãèªåã®ååå ã¯2014å¹´6æã®Local Chapter Meeting 2ndã ã£ãããã§ã
- OWASP Kansaiã¨ããã°åçãã¼ã§ãããï¼
- ææ°ã®æ¬¡ã®ã¹ãã¼ã¸å ¬é
2. OWARAI Top 10
ã»ãã¥ãªãã£ãã¿ãé¡æã«æ´»èºããã¦ãããç¬ãè¸äººããã«ããã¹ãã¼ã¸ã
ãã£ã¡ãããããã£ããæ®æ®µã¯èå¼±ã¨ã³ã¸ãã¢ã®æ¥å¸¸ã¨ããåç»ãå
¬éããã¦ããããã§ã
3. åä¾ã¨ä¿è·è ã¨ã»ãã¥ãªãã£æè
- 2000年以éã®å種ãµã¼ãã¹ã¨åä¾ã®å¹´é½¢/å¦å¹´
- 21ä¸ç´åé ã«çã¾ãã人ãæ¢ã«æ人
- LINEã£ã¦ãµã¼ãã¹éå§ãã10年以ä¸çµã£ã¦ãã®ãã»ã»ã»
- 2020年以éGIGAã¹ã¯ã¼ã«æ§æ³ã«ãã1人1å°ç«¯æ«ã®å®ç¾
- æå¸ã®å¦æ ¡æä¾ã®ç«¯æ«ã®ã«ã¼ã«ã«è¦ç¬ï¼ããã¦ãã«ã¼ã«ã®æãéæ¢ããã¤ã¯å¿ ãããï¼
- ãã®ä»ãªãã¬ã³ãã¿ãã
4. OWASP Top 10 Proactive Controls 2024ã§å§ããã»ãã¥ãªãã£
- æ¯æ°ã¥ãã«æããèªè»¢è»ã§å ç²å±±ç»ã£ã¦ããæ¥ãã®ã§æ¢ã«HPã¯2
- OWASP Top 10ã¨OWASP Top 10 Proactive Controlsã®éã
- Top 10
- ãªã¹ã¯ã示ãããã®
- Proactive Controls
- Top 10ã®ãªã¹ã¯ãèµ·ãããªãããã«ããããã®å®è£ ãªã¹ãï¼ååæ´æ°ã¯2018å¹´ï¼ããã®ãªã¹ãã¯ãã¹ã¦ã®ã¢ã¼ããã¯ãã¨éçºè ãç¥ã£ã¦ããã¹ã
- SSRFãåãåºããã¦ãã®ãã»ã»ã»
- 触ãããæ¸ããã¦ããªãã®ã§å¿ ãåèæç®ãèªããã¨
- Top 10
- Proactive Controls C1ã®èª¬æ
- äºåã«ã¢ã¯ã»ã¹å¶å¾¡ãå¾¹åºçã«è¨è¨ãã
- OWASP Top 10 Proactive Controlsã¯ãå æ¬çãªæè¡ãå®è·µã®éåã§ã¯ãªãåºçºç¹
5. EPSSï¼Exploit Prediction Scoring Systemï¼ã¢ãã¿ãªã³ã°ãã¼ã«ã®éçº
- ãã¢ã¨FAQã¯æ®å½±ç¦æ¢
- CVSS4.0ãç¨ããèå¼±æ§è©ä¾¡
- EPSS
- ã½ããã¦ã§ã¢ã®èå¼±æ§ãæªç¨ãããå¯è½æ§ï¼ç¢ºçï¼ãæ¨å®ããããã®ãã¼ã¿é§ååã®åãçµã¿
- æªç¨ãããèå¼±æ§ã«çç®ããèå¼±æ§ç®¡ç
- EPSSã¯æ¥ã
å¤ãæ´æ°ãããã®ã§åªå
度ä»ãã«ä½¿ãã«ããâã¢ãã¿ãªã³ã°ãã¼ã«ä½ã£ã
- LLMã§éçº
- 仮説ã®æ¤è¨¼ã«ã¯LLMã¯å½¹ç«ã¤
- ç·ã§ç¶ç¶çã«ã¢ãã¿ãªã³ã°ããã¹ã
6. BoFãAWSã®ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã¸ã®æºåã¨å¯¾å¿ã
- ã¢ã¯ã»ã¹ãã¼ãæ¼ãããã¨ã«ããå½±é¿ã®äºä¾
- è¨å®ä¸åã«ããS3ããæ
å ±ãæ¼ããã·ããªãªãé¡æã«ãAWSã®å種ãµã¼ãã¹ã使ã£ã¦ç¢ºèªãããã¢
- CloudTrail
- Athena
- åå¾ãããã¼ã¿éã§èª²éããããããã¯ã¨ãªã®æ¸ãæ¹ãããã£ããããã£ã¨ããéã«è²»ç¨ã«è·³ãè¿ãï¼Athenaã£ã¦ããããããã®ã§è©¦ãã¥ããã®ããã»ã»ã»ï¼
- GuardDuty
- éæ¤ç¥ã¨æ¤åºæ¼ããã¡ããã¡ãããã
- æè¿ã®S3ã¯ããã©ã«ãã§é常ã«å³ããå¶éãããã£ã¦ãããã7å¹´åã«æ§ç¯ããS3ã¯çµæ§ã¬ãã¬ããªã®ã§ããããä»ã«ãªã£ã¦ã¤ã³ã·ãã³ãã«ã¤ãªããã±ã¼ã¹ããã
ï¼æ¦å©åï¼
ãªã³ãªã¹ã»ãªã³ã¤ã«ï¼5ï¼
ã±ããè»æ¹ï¼34ï¼